Cyble·¢Ã÷ºÚ¿ÍÔÚ°µÍø³öÊÛÁ½ÒÚ¶àÖйú¹«ÃñµÄÐÅÏ¢£»£»£»£»£»£»Ñо¿Ö°Ô±Åû¶Zend FrameworkÖÐÔ¶³Ì´úÂëÖ´ÐÐÎó²î
Ðû²¼Ê±¼ä 2021-01-05CybleµÄÑо¿ÍŶӷ¢Ã÷ºÚ¿ÍÔÚ°µÍø³öÊÛÁ½ÒÚ¶àÖйú¹«ÃñµÄÐÅÏ¢¡£¡£¡£´Ë´Îй¶µÄÊý¾ÝÀ´×Ô¶à¸öƽ̨ºÍÈí¼þ£¬£¬£¬ÆäÖаüÀ¨730Íòºþ±±Ê¡¾£ÖÝÊй«°²ÏØ×¡ÃñµÄÉí·ÝÖ¤ºÅ¡¢ÐÔ±ð¡¢ÐÕÃû¡¢³öÉúÈÕÆÚ¡¢ÊÖ»ú¡¢µØµãºÍ´úÂëµÈÐÅÏ¢£¬£¬£¬4180Íò¸ö΢²©Óû§µÄÕ˺źÍÏìÓ¦µÄÊÖ»úºÅÂ룬£¬£¬ÒÔ¼°1.92ÒÚQQÓû§µÄÕ˺źÍÏìÓ¦µÄÊÖ»úºÅÂë¡£¡£¡£´Ë´Îй¶µÄÓëÖйú¹«ÃñÓйصļͼ×ÜÊýÁè¼Ý2ÒÚ¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/112966/deep-web/chinese-citizens-data-darkweb.html
2.д¹ÂڻÒÔÕÊ»§ÊÜÏÞ¶ÌÐÅΪÓÕ¶üÇÔÈ¡PayPalƾ֤
еĴ¹ÂڻÒÔÕÊ»§ÊÜÏÞ¶ÌÐÅΪÓÕ¶üÇÔÈ¡PayPalµÇ¼ƾ֤¡£¡£¡£´Ë´Î¹¥»÷»î¶¯Ã°³äPayPal·¢ËÍթƶÌÐÅ£¬£¬£¬Éù³ÆÓû§µÄÕÊ»§Êܵ½ÓÀÊÀÏÞÖÆ£¬£¬£¬Ðèµã»÷Á´½ÓÀ´ÑéÖ¤ÕÊ»§¡£¡£¡£¸ÃÁ´½Ó½«Óû§Öض¨Ïòµ½´¹ÂÚÒ³Ãæ£¬£¬£¬ÒÔÇÔÈ¡Óû§µÇ¼ƾ֤¡£¡£¡£±ðµÄ£¬£¬£¬ÔÚÓû§ÊäÈëµÇ¼ƾ֤ºó¸ÃÍøÕ¾»¹»á½øÒ»²½ÍøÂç¸ü¶àÏêϸÐÅÏ¢£¬£¬£¬ÀýÈçÐÕÃû¡¢³öÉúÈÕÆÚ¡¢µØµãºÍÒøÐÐÏêϸÐÅÏ¢µÈµÈ£¬£¬£¬ÒÔÓÃÓÚδÀ´µÄÉí·ÝµÁÓù¥»÷£¬£¬£¬Õë¶ÔÐÔµÄÓã²æÊ½´¹ÂÚ¹¥»÷»ò»á¼ûÓû§µÄÆäËûÕÊ»§¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/beware-paypal-phishing-texts-state-your-account-is-limited/
3.Ò½ÁÆ»ú¹¹GenRxÔâµ½ÀÕË÷¹¥»÷£¬£¬£¬»¼Õß¿µ½¡Êý¾Ýй¶
ÃÀ¹úµÄÒ½ÁÆ»ú¹¹GenRx PharmacyÔâµ½ÀÕË÷¹¥»÷£¬£¬£¬»¼Õß¿µ½¡Êý¾Ýй¶¡£¡£¡£¹¥»÷±¬·¢ÔÚ2020Äê9ÔÂ27ÈÕ£¬£¬£¬ºÚ¿ÍÌᳫÀÕË÷Èí¼þ¹¥»÷¡£¡£¡£¸Ã¹«Ë¾ÓÚµÚ¶þÌ죨9ÔÂ28ÈÕ£©·¢Ã÷Á˸û²¢×èÖ¹ÁËºÚ¿Í¶ÔÆäϵͳµÄ»á¼û¡£¡£¡£¸Ã¹«Ë¾³Æ´Ë´ÎÍøÂç¹¥»÷²¢Î´Àֳɣ¬£¬£¬ÆäÓªÒµ²¢Î´Êܵ½Ó°Ï죬£¬£¬µ«ºÚ¿ÍÒѾ»á¼û²¢É¾³ýÁËijЩ»¼ÕßÊý¾Ý£¬£¬£¬°üÀ¨»¼ÕßID¡¢ÉúÒâID¡¢ÐÕÃû¡¢µØµã¡¢µç»°ºÅÂë¡¢³öÉúÈÕÆÚ¡¢ÐԱ𡢹ýÃô¡¢ÓÃÒ©Çåµ¥¡¢¿µ½¡ÍýÏëÐÅÏ¢ºÍ´¦·½ÐÅÏ¢µÈ¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://latesthackingnews.com/2021/01/04/genrx-pharmacy-ransomware-attack-resulted-in-data-breach/
4.ÓÊÂÖ¹«Ë¾AIDAÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬Í¨Ñ¶Ð§ÀÍÔÝʱÖÐÖ¹
µÂ¹úÓÊÂÖ¹«Ë¾AIDAÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬Í¨Ñ¶Ð§ÀÍÔÝʱÖÐÖ¹¡£¡£¡£AIDA³ÆÆäµç»°ÏµÍ³ºÍµç×ÓÓʼþϵͳÖÐÖ¹£¬£¬£¬±»ÆÈ×÷·Ï2020Äê12ÔÂ26ÈÕµÖ´ïµÄÓÊÂÖµÄÐг̡£¡£¡£Ö»¹ÜAIDA²¢Î´Í¸Â¶Ðí¶àϸ½Ú£¬£¬£¬µ«µÂ¹úýÌ屨µÀÆäÔâµ½ÁËÍøÂç¹¥»÷£¬£¬£¬Ò»Ð©´¬ÉϵÄÂÿÍÒ²ÌåÏÖ´¬²°Óë×ܲ¿Ö®¼äµÄͨѶÖÐÖ¹¡£¡£¡£´Ë´Î¹¥»÷ÊÂÎñ»¹Ó°ÏìÁËCosta CruiseºÍCarnival Maritime¡£¡£¡£±ðµÄ£¬£¬£¬Databreaches.netÍÆ²âAIDAÔâµ½ÁËDoppelpaymerÀÕË÷Èí¼þ¹¥»÷¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://latesthackingnews.com/2021/01/03/aida-ships-face-service-disruptions-ransomware-attack-suspected/
5.Ñо¿Ö°Ô±Åû¶Zend FrameworkÖÐÔ¶³Ì´úÂëÖ´ÐÐÎó²î
Ñо¿Ö°Ô±Ling YizhouÅû¶Zend Framework3.0.0ÖеÄÒ»¸ö²»¿ÉÐŵķ´ÐòÁл¯Îó²î£¨CVE-2021-3007£©¡£¡£¡£Zend FrameworkµÄ×°ÖÃÁ¿Áè¼Ý5.7ÒڴΣ¬£¬£¬±»ÓÃÀ´¹¹½¨ÃæÏò¹¤¾ßµÄwebÓ¦ÓóÌÐò¡£¡£¡£¸ÃÎó²î±£´æÓÚStreamÀàµÄÎö¹¹º¯ÊýÖУ¬£¬£¬¿É±»ÓÃÀ´¶ÔÒ×Êܹ¥»÷µÄPHPÓ¦ÓþÙÐÐÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©¹¥»÷¡£¡£¡£±ðµÄ£¬£¬£¬ZendÓÚ2020Äê1ÔÂǨáãµ½LaminasÏîÄ¿£¬£¬£¬ÔÚijЩ°æ±¾µÄLaminasÖÐÒ²±£´æÉÏÊöStream.phpÀ࣬£¬£¬Òò´Ë²¿·ÖʹÓÃLaminas¹¹½¨µÄÓ¦ÓÃÒ²¿ÉÄÜ»áÊܵ½Ó°Ïì¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/zend-framework-remote-code-execution-vulnerability-revealed/
6.IDGÐû²¼2020ÄêÇå¾²ÖØµãÑо¿µÄÆÊÎö±¨¸æ
IDGÐû²¼ÁË2020ÄêÇå¾²ÖØµãÑо¿µÄÆÊÎö±¨¸æ£¬£¬£¬Ö¼ÔÚ¸üºÃµØÏàʶ×éÖ¯ÏÖÔÚºÍÀ´Äê¹Ø×¢µÄÖÖÖÖÇå¾²ÏîÄ¿¡£¡£¡£¸Ã±¨¸æÖ¸³ö£¬£¬£¬Áè¼ÝÈý·ÖÖ®Ò»£¨37£¥£©µÄÈËÒÔΪ£¬£¬£¬COVID-19ºÍÀͶ¯Á¦±ä»»µÈÒâÍâÕýÆÈʹËûÃǽ«Öصã´ÓÕ½ÂÔÇ徲ʹÃüÖÐ×ªÒÆ³öÀ´£»£»£»£»£»£»Èý·ÖÖ®Ò»µÄ¾öÒéÕßÌåÏÖ£¬£¬£¬ËûÃÇ2021ÄêÇå¾²Ô¤Ë㽫¸ßÓÚCOVID-19֮ǰµÄÔ¤Ë㣬£¬£¬41£¥µÄÈËÌåÏÖ×ÜÌåÇå¾²Ô¤Ë㽫ÔÚδÀ´12¸öÔÂÄÚÔöÌí£»£»£»£»£»£»´ó´ó¶¼£¨87£¥£©ÊÜ·ÃÕßÃ÷È·ÔÚÒÑÍùÒ»ÄêÖÐÔì³ÉÇå¾²ÊÂÎñµÄÔµ¹ÊÔÓÉ¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.idg.com/tools-for-marketers/2020-security-priorities-study/